Ravindra BagaleCourses & study guides

48. CEH v13 Exam Modules Map and Practice Questions

48.6 CEH-Style Practice Questions – Set A (Modules 01–10)

Set A = Modules 01–10. Conceptual / defensive. Multiple choice + short answers. Answer line after each. Chala try kara – Hint nako pehle!

Q1. (Module 01) Before any Nmap scan in a professional engagement, what must exist first?

A. A Metasploit workspace
B. Written authorisation and agreed scope
C. A public CVE blog post
D. A honeypot on the target LAN
Answer: B. Ethics and law first – scope on paper.

Q2. (Module 01) CIA triad – which pillar does a ransomware encryption event hit hardest first?

A. Confidentiality only forever
B. Integrity of marketing copy
C. Availability of systems and data for users
D. Physical CCTV only
Answer: C. Availability (and often integrity of data state) – users lose access.

Q3. (Module 02) Passive footprinting mainly uses:

A. Exploit kits against the mail server
B. Public sources without directly touching the target much
C. SQL injection on the login form
D. ARP spoofing on the OT VLAN
Answer: B. OSINT / public sources – lower direct touch.

Q4. (Module 02) Amass in passive mode is best described as:

A. A ransomware encryptor
B. A subdomain discovery approach using public/DNS intelligence sources
C. A wireless cracker
D. A session-cookie editor
Answer: B. See ch36 – purpose awareness, OWN/authorized domains only.

Q5. (Module 03) Which Nmap-style activity belongs only on OWN or authorised ranges?

A. Updating Kali
B. Host/port discovery scans
C. Reading a public CVE page
D. Enabling MFA on your Gmail
Answer: B. Scanning needs authorisation.

Q6. (Module 03) A Blue team sees a sudden burst of SYN packets to many ports on one EIP. Likely interpretation?

A. Normal DNS recursion
B. Possible port scan / recon noise
C. Successful TLS handshake only
D. SPF pass for email
Answer: B. Mass SYN across ports often means scan activity – investigate.

Q7. (Module 04) Enumeration differs from basic port scanning because it:

A. Always encrypts disks
B. Pulls extra details from open services (users, shares, banners) after ports are known
C. Replaces the need for patching
D. Is legal on any cafe Wi-Fi
Answer: B. Extra detail phase – still needs authorisation.

Q8. (Module 04) Closing null-session style SMB risks and logging LDAP binds primarily helps against:

A. DNSSEC misconfig only
B. Over-friendly enumeration of directory/share data
C. AES-GCM
D. Certbot renewals
Answer: B. Enum hardening.

Q9. (Module 05) Best first use of a vulnerability scanner report?

A. Blindly launch every exploit
B. Prioritise by exposure and severity, then patch / mitigate
C. Publish the full report on Twitter
D. Disable all logging
Answer: B. Triage and fix – scanner ≠ automatic attack.

Q10. (Module 05) For Sahyadri’s public web VM, which finding usually jumps the queue?

A. Info-level missing HTTP header on an internal printer
B. Critical CVE on the internet-facing web framework
C. Lab-only outdated package on host-only .20 with no route out
D. A typo in a comment
Answer: B. Internet-facing criticals first.

Q11. (Module 06) Least privilege mainly means:

A. Everyone is Administrator for convenience
B. Accounts get only the access needed for their role
C. Disabling TLS
D. Sharing one root password on WhatsApp
Answer: B.

Q12. (Module 06) After a weak password is guessed on an OWN lab SSH, Blue’s durable fixes include:

A. Posting the password in a gist
B. Key-based auth, fail2ban-style controls, MFA where possible, monitoring failed logins
C. Opening port 22 to 0.0.0.0/0 forever
D. Turning off all logs
Answer: B.

Q13. (Module 07) Which statement is safest training practice for malware?

A. Email mystery samples to friends
B. Study concepts and use isolated lab samples under guidance – never detonate on production
C. Disable AV globally at the shop
D. Pay every ransom immediately without IR advice
Answer: B.

Q14. (Module 07) Offline / tested backups most directly support recovery from:

A. SPF alignment only
B. Ransomware / destructive malware availability loss
C. CSS styling bugs
D. Certificate Transparency logs
Answer: B.

Q15. (Module 08) Cleartext FTP on a shared segment is risky mainly because:

A. FTP cannot transfer files
B. Credentials and data may be sniffed by others on the path
C. FTP forces Argon2
D. FTP disables ARP
Answer: B. Prefer SFTP/FTPS patterns.

Q16. (Module 08) Wireshark in a SOC-oriented story is primarily a tool to:

A. Encrypt S3 buckets
B. Inspect packets for troubleshooting and detection learning
C. Replace IAM
D. Mine Bitcoin on EC2
Answer: B.

Q17. (Module 09) Best single control that stops many credential-phishing successes:

A. Longer company motto
B. MFA plus user reporting culture
C. Disabling HTTPS
D. Public RDP with blank password
Answer: B.

Q18. (Module 09) A consented phishing simulation at Raja-Rani Traders requires:

A. No management awareness
B. Clear authorisation, education goal, and no real harm to customers
C. Targeting a rival shop’s CEO
D. Publishing clicked passwords online
Answer: B.

Q19. (Module 10) DoS/DDoS primarily targets which CIA pillar?

A. Confidentiality of one password file only
B. Integrity of a single JPG
C. Availability for legitimate users
D. Non-repudiation certificates only
Answer: C.

Q20. (Module 10) Which is an acceptable Blue response pattern to volumetric floods?

A. Launch your own flood at the suspected source from home broadband
B. Rate limits, filtering, capacity/DDoS protection services, and an IR playbook
C. Disable all monitoring to save CPU
D. Open every port so traffic "spreads out"
Answer: B. Never counter-attack from your laptop.

Q21. (Short) Name the five high-level ethical hacking phases in order (awareness level).

Answer: Reconnaissance, scanning, gaining access, maintaining access, covering tracks – taught as a model; real work also emphasises reporting and remediation. Always authorised.

Q22. (Short) Why is host-only 192.168.56.0/24 used in this book’s Kali labs?

Answer: To keep offensive traffic inside a private lab network you control, reducing accidental scans of production or neighbour networks.

Q23. (Short) Module 04: give one Blue control for DNS enumeration risk.

Answer: Restrict zone transfers (AXFR) to authorised secondaries; monitor; consider split DNS.

Q24. (Short) Module 06: why are password dumps in exam answers a bad habit?

Answer: Real dumps and crack recipes can be abused; discuss controls (MFA, hashing, rate limits) and OWN-lab practice only.

Q25. (Short) Module 09: name three email authentication building blocks defenders cite.

Answer: SPF, DKIM, and DMARC.

Red team (attacker) does Blue team (defender) detects / stops
Practices Set A by hacking random public IPs Practices on OWN lab; answers emphasise controls
Skips Modules 01 ethics questions Treats Q1-style items as career filters

Ravindra Bagale's Tip

In MCQs, watch for absolute words like "always / never / only" – they are usually a trap. But on ethics, "written authorisation first" is almost always right. Got it?

Lab

Score Set A: mark Green/Yellow/Red. Re-read book chapters for every Red item before Set B. Pair with Shraddha – she asks Q, you answer in clean English aloud.